Releasing seemingly innocuous functions of a data set can easily compromise the privacy of individuals, whether the functions are simple counts [35]orcomplexmachine learning models like deep neural networks [52,30].
In this paper,we consider a setting where sensitive attributes indirectly manifest in an auxiliary representation graphrather than being directly observed.
In the context of localization, however, there is no natural definition of classes. Therefore, images areartificially separated intopositive/negativeclasses with respect to the chosen anchor images, based on some geometric proximity measure.